
Security News
Re-Enabled GitHub Actions Expose Thousands of Repositories to Mini Shai-Hulud
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.
@aishelf/service
Advanced tools
AIShelf local service for cross-platform file access — server only; see @aishelf/cli for the command-line front door
A lightweight background service that powers AIShelf clients - including the VS Code extension and other future clients. It acts as a centralized source of workflows, skills, prompts, and rules for all your AI tools across your local machine, handling authentication and registry management so that AIShelf tools can securely access your shared AI resources.
For installation instructions and documentation, visit aishelf.dev/docs/installation.
MIT
FAQs
AIShelf local service for cross-platform file access — server only; see @aishelf/cli for the command-line front door
The npm package @aishelf/service receives a total of 11 weekly downloads. As such, @aishelf/service popularity was classified as not popular.
We found that @aishelf/service demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.

Research
/Security News
A malicious Firefox extension fetches its payload after installation to evade detection, steal Google session cookies, and automate account takeover.

Research
/Security News
The compromise affects MemTensor's MemOS, an open source memory framework for large language models (LLMs) and AI agents. Both npm package @memtensor/memos-cloud-openclaw-plugin and the PyPI package MemoryOS are compromised. They drop cross-platform Go binaries that exfiltrate developer secrets.